OWASP MCP Top 10: What a Gateway Fixes — and What It Doesn't
The OWASP MCP Top 10 (v0.1, beta) names ten risk categories for Model Context Protocol deployments. Mapped against a gateway’s enforcement pipeline, not one of them closes fully: some attack paths disappear by construction, others depend on a default that ships switched off, and MCP06 sits outside the boundary. With the exposure figures from arXiv 2608.00150, the NSA AISC design considerations, and the MCP06 title discrepancy on OWASP’s own page.